Business Continuity Management Planning Methodology

Size: px
Start display at page:

Download "Business Continuity Management Planning Methodology"

Transcription

1 , pp Business Continuity Management Planning Methodology Dr. Goh Moh Heng, Ph.D., BCCLA, BCCE, CMCE, CCCE, DRCE President, BCM Institute Managing Director, GMH Continuity Architects Abstract This paper explains the concept of business continuity management (BCM) with the specific focus on the BCM planning process and methodology. Before entering into the maintenance phase of any BCM program, the Organization BCM Coordinator needs to ensure that the project phases of the BCM planning methodology are succinctly implemented to meet the organization s BCM objectives. This paper is an update of an earlier paper written in 1996 incorporating the author s subsequent experiences and implementation while he is working in the financial regulatory environment. This BCM methodology is aligned with the BCM standard ISO The intent in the following dialog is to explain the BCM planning process briefly. Keywords: Business Continuity planning methodology, Project Management, Risk Analysis and Review, Business Impact Analysis, Business Continuity Strategy, Plan Development, Testing and Exercising, Program Management, ISO Introduction Business Continuity Management [1] is a holistic management process that identifies potential threats to an organization and the impacts to business operations those threats, if realized, might cause, and which provides a framework for building organizational resilience with the capability for an effective response that safeguards the interests of its key stakeholders, reputation, brand and value-creating activities. Businesses are subject to disruptions of varying severity. An incident, emergency or event, if not managed properly, can escalate to become a disaster or crisis. Besides creating an unplanned disruption that can tarnish an organization's image, in the extreme case, this incident if not properly managed can result in significant physical or environmental damage. It may cause significant injuries to employees or even death. For example, a fire outbreak if not brought under control quickly can result in grave consequences. Organizations should, therefore, be prepared for an incident before it occurs to minimize its impact should it happen. 2. BCM Planning Methodology The BCM planning methodology (Figure 1), like any other planning process, provides a framework for requirements, effort, and deliverables, each phase leading into the next in an endlessly repeating cycle. In real life, many of the steps or phases can be conducted concurrently. While these steps provide visual clues as to the amount of execution time to take, they are used as a reference and do not represent an absolute percentage of the time. ISSN: IJDRBC Copyright c2015 SERSC

2 Figure 1. BCM Planning Methodology This BCM planning methodology [2] started with the author being tasked to develop and implement a business continuity planning methodology for a large international UKbased bank. The planning methodology has been subjected to the rigor of both successful global implementation of BC plans for the bank's 52 franchisees. This methodology has been subjected to the highest level of academic scrutiny as part of a Doctor of Philosophy dissertation [3]. In researching for this thesis, more than 200 types of proprietary BCM processes and methodologies had been evaluated. For more than a decade since the completion of the thesis, the BCM planning methodology had undergone an evolutionary process of continuous improvement, to form the framework for BCM Institute s training curriculum. 3. Definition As defined in BCMPedia [4], the BCM planning methodology is the planning process for the implementation of any BC plan. The phases are as follows: Project Management. Risk Analysis and Review. Business Impact Analysis. Business Continuity Strategy. Plan Development. Testing and Exercising. Program Management. 4. Project Management The first step in implementing the BCM planning methodology in any organization is to set up the needed Executive Management structure, to support the BCM planning process [5]. Here is where we confirm the inclusion of the business units and the business functions in the scope and the roles and responsibilities of each party participating in the project. This inclusion is to ensure the efficient completion of task assignments and time goals, which will have to be set at a later stage of the project. The BC project planning team will need to: Obtain the commitment of Heads of Business Units and their staff members, and involve them in the BCM planning process. 10 Copyright c 2015 SERSC

3 Identify and mobilize the business units resources. Begin the information gathering process What does the Project Management Entail? The entire project management process involves the following steps. Establish the need for BCM planning. Research the work in the areas of BCM. Develop a BCM planning framework. Define the scope, objectives, and assumptions. Manage the BCM planning process. Establish a BCM project planning committee and team. Develop an action plan and schedule. Establish a budget. Obtain commitment and approval. Manage deadlines and milestones. Build and maintain teamwork. The detailed breakdown of the steps can be found in the first book [1] of the BCM Book Series. 5. Risk Analysis and Review The Risk Analysis and Review phase is the detailed analysis of risks, vulnerabilities (exposures) and probabilities [6] and is a component of risk assessment. The Risk Analysis & Review phase along with the following Business Impact Analysis phase is key fundamental elements of an organization s BCM Program. The Risk Analysis & Review phase is not the end game but rather a starting point in the BCM planning process. It is an industry-recognized approach to helping an organization determine which disruptive events are they vulnerable. How to address these vulnerabilities and where they can maximize the value of the dollars they spend on their unique BCM efforts. The purpose of a Risk Analysis & Review phase is the mitigation or minimizing of the risks and threats to the organization. The major steps and considerations during the Risk Analysis & Review [7] process include: Assess the risk. Assess the control options. Assess the cost and the effectiveness of risk controls. Establish the Key Disaster Scenario. Report to the Executive Management. Implement, maintain and monitor the effectiveness of controls. Copyright c 2015 SERSC 11

4 6. Business Impact Analysis The Business Impact Analysis (BIA) phase refers to the process of identifying an organization s Critical Business Functions and analyzing the potential disruptive impact to the business [7]. The Business Impact Analysis phase is to: Assess the impact of a disruption to any functional area or business operations within the organization. Determine the extent to which primarily functional and operational dependencies exist within the organization. Establish the restoration priorities and sequence of the critical IT applications and essential business functions What does the Business Impact Analysis Process Entail? The entire Business Impact Analysis process involves the following steps: Gather Information. Design the Business Impact Analysis Questionnaires. Gather initial information about business functions, support systems and IT applications through the use of Business Impact Analysis Questionnaires. Verify and Analyze Information. Validate the content of the submitted Business Impact Analysis Questionnaires with Business Unit BCM Coordinators. Conduct face-to-face interviews with Business Unit BCM Coordinators to verify the accuracy of the information presented. Analyze information to determine priorities for recovery of business operations, systems, and IT applications. Establish a Recovery Time Objective for each Critical Business Functions, which is the time taken from disruption until recovery of services. Document and Present Findings. Prepare the executive summary and the Business Impact Analysis report. Include recovery priorities supported by graphs, charts, and other working aids. Present a set of findings to the Executive Management in written and oral reports. Update the Executive Management on the subsequent steps in the BCM planning process. 7. Business Continuity Strategy The development of the BC Strategy is the process to determine and select operating strategy to maintain or continue the critical business functions or product and services during a disaster [8] What does the Development of BC Strategy Entail? The entire BC Strategy [8] process involves the following stages: 12 Copyright c 2015 SERSC

5 Initiate the BC Strategy Project and Design. Understand the development process for BC Strategy. Evaluate current status and arrangement. Prepare a project plan. Develop and Consolidate BC Strategy. Design working document for completing the BC Strategy information. Conduct the BC Strategy workshop. Design and develop BC Strategy by the business units BCM coordinators and their heads. Review and consolidate submissions from business units by the organizational BCM project team. Finalize Strategy and Obtain Acceptance for the strategy. Validate design of the individual and corporate BC strategy. Finalize the corporate-level BC Strategy. Obtain approval from Executive Management. 8. Plan Development In the plan development phase [9], you will need to identify all the procedures and resources necessary to initiate the BC documentation. The BC plan will contain all the pertinent details from the Business Impact Analysis and BC Strategy Phases. The completed plan is an important document, as all staff in the business units will rely on it for instruction and guidance in the event of a disaster. It is, therefore, necessary for the BC plan to be well structured and developed in a series of logical steps. As the team proceeds, please keep in mind that the BC procedures should be entirely self-contained and simple to use. The BC plan will be based on all the procedures and priorities agreed upon by the executive management so that the need to refer or make decisions in a disaster will be kept to an absolute minimum What does the Plan Development Phase Entail? The entire Plan Development [9] process involves the following stages. Determine the Organization of the Plan Document. Design and develop BC plan template. Determine and finalize the recovery organization. Conduct a Plan Writing Workshop to Guide BC Plan Writers. Facilitate the completion of the plan template by individual business units BCM Coordinators. Finalize the production of the BC Plan. Validate the content of BC plans by business units' BCM Coordinators and Heads of Business Units for their completeness and coverage. Copyright c 2015 SERSC 13

6 Sign-off by heads of respective business units. 9. Testing and Exercising Testing & Exercising is needed to ensure the business continuity (BC) plan works [10]. The BC plan must be tested to prove its validity. Testing is intended to find errors and omissions in the BC plan procedures. These corrected omissions or errors can be reported to all concerned parties and subsequently. The process of simulating a recovery based on the procedures within the BC document also prepares the relevant staff to function at the alternate site and verifies the adequacy of the alternative site. Ultimately, the Testing & Exercising phase ensures the integrity of the complete business continuity plan, with appropriately documented procedures to handle all likely situations What does Testing and Exercising Entail? The entire Testing and Exercising [10] process involves the three main stages: Designing the Test Program. Executing the Test. Assessing and correcting the results of the tests and exercises. In stage 1, which is the Designing the Test Program, the components of this stages includes. The First Component is the development of a corporate-wide test and exercise program. The appointed person responsible for BC plan should develop this program, and it will be done in consultation with executive management. The program should identify all the tests and exercises that are required. The Second Component is for Specific Tests defined within the test program; the following questions should be asked? What is the aim of the test? What does each test try to prove? What is the scope of the test? To what extent do they wish to test? Who will be involved? Which components should they test? What is the method that will be used for conducting the test? How will the test be performed? The Third Component is an Evaluation mechanism that must be developed to assess whether the tests were successful. Specific, measurable criteria must be established to decide whether each test achieves a pass or fail result. In stage 2, this entails running the Test. Here is where the actual test is executed based on the planned scope of testing. In the last stage, the test results are assessed against the pre-determined criteria. An evaluation of the outcome of causes of any deviations, either through errors or omissions, and corrections are made to the BC plan. As part of the continuous improvement process, there is always a need to fine-tune the test plan where relevant, for future testing. The team should perform tests and exercises on all aspects of a BC plan, such as Information Technology (IT) system switch-over, telephone notification call trees, and evacuation methods. These tests should be discussed with relevant staff to determine the most appropriate model and test schedule. Testing helps identify vulnerabilities and changes in the organizational environment and allows the renewal of the BC plan accordingly. For the tests to be valid, it must challenge the recovery needs of the organization. Each member of the BC team is strongly recommended to be involved in some form of testing twice every year. A test policy to revise the readiness of their plans should be developed and published. 14 Copyright c 2015 SERSC

7 A mandatory corporate policy to perform "at least once per year" testing should be published and endorsed by Executive Management. This regular distribution of the resultant revised BC plans to all recovery personnel. 10. Program Management Once the BCM planning project completes, the next challenge is to keep the BCM program effort alive. It is essential to emphasize continuously that, in the event of a disaster, BCM is the key to ensuring the safety of all people in the organization as well as the survivability of the organization. The objective of the Program Management phase is to establish an on-going system to ensure the validity of critical business functions, BC Strategy and documented recovery procedures [11]. The ultimate goal is the recoverability of the business processes in the organization What does BCM Program Management Entail? Some of the activities that have to be completed under the Program Management [11] phase, and they ensure that the: BC Plan is consistent with the most current business operational setup. BC Plan is available, accessible and distributed to the recovery team. Maintain BC Plan to an acceptable standard, efficiency, and effectiveness. Planning efforts enable the prompt and correct response of the staff in a disaster. BC Plan is consistent with international standards. In summary, it is important to maintain the BC Plan regularly and updated and kept actually. The primary considerations in this process include the: Maintenance process. Incorporation of the training & awareness phase to institute it as part of the organizational training program. Development of advanced level testing and exercising. Constant review and audit of the BC plan and its preparedness. Embedding of the BCM mindset and culture into the organization. 11. Conclusion This planning methodology covers the Plan, Do, Check and Act components of the Plan-Do-Check-Act or PDCA cycle as mandated by any typical ISO management system. The intent is to ensure that BCM process develop a workable BC plan. The BCM planning methodology continues to be the cornerstone for all BCM planning activities. This methodology includes a requirement for Pandemic Flu planning [12], IT disaster recovery planning [13] and crisis management [14]. References [1] ISO, Editor, ISO22301:2012 Societal Security Business Continuity Management Systems Requirements, (1st ed., p. 24), International Organization for Standardization, Switzerland, (2012). [2] M. H. Goh, Developing a suitable business continuity planning methodology, Information Management & Computer Security, vol. 4, no. 2, (1996), pp [3] M. H. Goh, Editor, Business Continuity Planning for Banks in Asia: A Case Study in Standard Chartered Bank, University of South Australia, (1999). Copyright c 2015 SERSC 15

8 [4] M. H. Goh, Editor, CMpedia: A Wiki Glossary for Business Continuity Management, Crisis Management and Disaster Recovery (4th ed., p. 200), BCM Institute, Singapore. (2013). [5] M. H. Goh, Editor, Managing Your Business Continuity Planning Project (2nd ed., p. 166), GMH Pte Ltd, Singapore. (2008). [6] M. H. Goh, Editor, Analyzing & Reviewing the Risks for Business Continuity Planning, (2nd ed., p. 148), GMH Pte Ltd, Singapore, (2008). [7] M. H. Goh, Editor, Conducting Your Impact Analysis for Business Continuity Planning, (2nd ed., p. 130), GMH Pte Ltd, Singapore, (2008). [8] M. H. Goh, Editor, Developing Recovery Strategy for Your Business Continuity Plan, (1st ed., p. 104), GMH Pte Ltd, Singapore, (2005). [9] M. H. Goh, Editor, Implementing Your Business Continuity Plan, (2nd ed., p. 104). GMH Pte Ltd, Singapore, (2010). [10] M. H. Goh, Editor, Testing and Exercising Your Business Continuity Plan, (2nd ed., p. 160), GMH Pte Ltd, Singapore, (2006). [11] M. H. Goh, Editor, Managing & Sustaining Your Business Continuity Management Program, (1st ed., p. 190), GMH Pte Ltd, Singapore, (2007). [12] M. H. Goh, Editor, A Manager s Guide to to Implement Your Infectious Disease Business Continuity Plan, (1st ed., p. 128), GMH Pte Ltd, Singapore, (2015). [13] M. H. Goh, Editor, A Manager s Guide to Managing and Implementing Your IT Disaster Recovery Plan, (1st ed., p. 208), GMH Pte Ltd, Singapore, (2010). [14] M. H. Goh, Editor, A Manager s Guide to Implement Your Crisis Management Plan, (1st ed., p. 208), GMH Pte Ltd, Singapore, (2015). Author Dr. Goh Moh Heng, Dr Goh is the President of BCM Institute and the Managing Director of GMH Continuity Architects a specialized BCM Consulting firm. His primary areas of expertise include Business Continuity Management (BCM), Disaster Recovery Planning (DRP), ISO22301 BCM Audit and Crisis Management. Since 2011, Moh Heng has assisted more than 20 organizations, particularly those operating in the Asia Pacific and Middle-East Region in their successful implementation of their Business Continuity Management System (BCMS) and achieving their BS 25999/ SS 540 / ISO organization certification. Prior to establishing BCM Institute and GMH BCM Consulting, Dr Goh held senior positions with a number of large organizations. During his career with the Government of Singapore Investment Corporation (GIC), he was responsible for all aspects of its BCM and crisis management. At Standard Chartered Bank Plc, he saw to the global implementation of its BCM and planning. He also managed the BCM practice at PricewaterhouseCoopers. Currently, Dr Goh is an expert panel member of the Asia-Pacific Economic Cooperation (APEC) Network on Improving SME Disaster Resilience (since 2011) and JICA-ASEAN study to enhance resiliency of industrial areas against natural disasters (since 2012). In May 2012, Dr Goh Moh Heng became the first Asian in the 16th year of tradition, to be awarded the "Business Continuity Lifetime Achievement Award" in London, United Kingdom by the Continuity, Insurance and Risk (CIR) Magazine. In January 2013, Dr Goh Moh Heng received the National BCM Awards 2013 from Singapore Business Federation and SPRING Singapore. 16 Copyright c 2015 SERSC

Business Continuity Planning (BCP) 101

Business Continuity Planning (BCP) 101 2011/EPWG/WKSP/004 Intro 1 Business Continuity Planning (BCP) 101 Submitted by: Business Continuity Management Institute Workshop on Private Sector Emergency Preparedness Sendai, Japan 1-3 August 2011

More information

Introduction to Business Continuity Planning

Introduction to Business Continuity Planning Introduction to Business Continuity Planning Business Continuity and Disaster Resilience Forum May 10, 2012 Rizal Ballroom A, Makati Shangri-la Manila, Philippines Dr Goh Moh Heng President BCM Institute

More information

Crisis Communication and Management: Lessons from Some Recent Crises/ Disasters

Crisis Communication and Management: Lessons from Some Recent Crises/ Disasters Crisis Communication and Management: Lessons from Some Recent Crises/ Disasters Dr Goh Moh Heng President 1 BCM Institute We are a global convergence of thought leadership in Business Continuity, Disaster

More information

By. Mr. Chomnaphas Tangsook Business Director BSI Group ( Thailand) Co., Ltd

By. Mr. Chomnaphas Tangsook Business Director BSI Group ( Thailand) Co., Ltd BS 25999 Business Continuity Management By. Mr. Chomnaphas Tangsook Business Director BSI Group ( Thailand) Co., Ltd 1 Contents slide BSI British Standards 2006 BS 25999(Business Continuity) 2002 BS 15000

More information

Shankar Gawade VP IT INFRASTRUCTURE ENAM SECURITIES PVT. LTD.

Shankar Gawade VP IT INFRASTRUCTURE ENAM SECURITIES PVT. LTD. Business Continuity Management & Disaster Recovery Planning Presented by: Shankar Gawade VP IT INFRASTRUCTURE ENAM SECURITIES PVT. LTD. 1 What is Business Continuity Management? Is a holistic management

More information

The PNC Financial Services Group, Inc. Business Continuity Program

The PNC Financial Services Group, Inc. Business Continuity Program The PNC Financial Services Group, Inc. Business Continuity Program subsidiaries) 1 Content Overview A. Introduction Page 3 B. Governance Model Page 4 C. Program Components Page 4 Business Impact Analysis

More information

Business Continuity Management Framework 2014 2017

Business Continuity Management Framework 2014 2017 Business Continuity Management Framework 2014 2017 Blackpool Council Business Continuity Framework V3.0 Page 1 of 13 CONTENTS 1.0 Forward 03 2.0 Administration 04 3.0 Policy 05 4.0 Business Continuity

More information

Business Continuity Policy

Business Continuity Policy Business Continuity Policy 1 NHS England INFORMATION READER BOX Directorate Medical Commissioning Operations Patients and Information Nursing Trans. & Corp. Ops. Commissioning Strategy Finance Publications

More information

ISO 22301 BUSINESS CONTINUITY MANAGEMENT SYStEMS (BCMS) EXPERT IMPLEMENTER

ISO 22301 BUSINESS CONTINUITY MANAGEMENT SYStEMS (BCMS) EXPERT IMPLEMENTER ISO 22301 BUSINESS CONTINUITY MANAGEMENT SYStEMS (BCMS) EXPERT IMPLEMENTER COMPETENCY LEVEL COMPETENCY WHICH LEVEL SHOULD I BE STARTING MY BUSINESS CONTINUITY TRAINING? KNOW DO BCM-230 BCM-330 I am new

More information

Temple university. Auditing a business continuity management BCM. November, 2015

Temple university. Auditing a business continuity management BCM. November, 2015 Temple university Auditing a business continuity management BCM November, 2015 Auditing BCM Agenda 1. Introduction 2. Definitions 3. Standards 4. BCM key elements IT Governance class - IT audit program

More information

www.td.com.au Business Continuity - IT Disaster Recovery Discussion Paper - - Commercial in Confidence Version V2.0R Wednesday, 5 September 2012

www.td.com.au Business Continuity - IT Disaster Recovery Discussion Paper - - Commercial in Confidence Version V2.0R Wednesday, 5 September 2012 Business Continuity - IT Disaster Recovery Discussion Paper - - Version V2.0R Wednesday, 5 September 2012 Commercial in Confidence Melbourne Sydney 79-81 Coppin St Level 2 Richmond VIC 3121 414 Kent St

More information

Company Management System. Business Continuity in SIA

Company Management System. Business Continuity in SIA Company Management System Business Continuity in SIA Document code: Classification: Company Project/Service Year Document No. Version Public INDEX 1. INTRODUCTION... 3 2. SIA S BUSINESS CONTINUITY MANAGEMENT

More information

BT Conferencing Business Continuity Management. Planning to stay in business

BT Conferencing Business Continuity Management. Planning to stay in business BT Conferencing Business Continuity Management Planning to stay in business Planning for the unexpected In today s connected world, businesses are increasingly dependent on their communications and networked

More information

Business Continuity Management Policy

Business Continuity Management Policy Business Continuity Management Policy Business Continuity Policy Version 1.0 1 Version control Version Date Changes Author 0.1 April 13 1 st draft PH 0.2 June 13 Amendments in line with guidance PH 0.3

More information

Business Continuity Policy

Business Continuity Policy Page 1 of 16 Business Continuity Policy Issue Date: Aug 2013 Document Number: 00241 Prepared by: Business Management and Continuity Senior Manager Next Review Date: April 2014 Page 2 of 16 NHS England

More information

Proposal for Business Continuity Plan and Management Review 6 August 2008

Proposal for Business Continuity Plan and Management Review 6 August 2008 Proposal for Business Continuity Plan and Management Review 6 August 2008 2008/8/6 Contents About Newton IT / Quality of our services. BCM & BS25999 Overview 2. BCM Development in line with BS25999 3.

More information

Business Continuity Policy

Business Continuity Policy Business Continuity Policy Page 1 of 15 Business Continuity Policy First published: Amendment record Version Date Reviewer Comment 1.0 07/01/2014 Debbie Campbell 2.0 11/07/14 Vicky Ryan Updated to include

More information

www.pwc.com Business Resiliency Business Continuity Management - January 14, 2014

www.pwc.com Business Resiliency Business Continuity Management - January 14, 2014 www.pwc.com Business Resiliency Business Continuity Management - January 14, 2014 Agenda Key Definitions Risks Business Continuity Management Program BCM Capability Assessment Process BCM Value Proposition

More information

The PNC Financial Services Group, Inc. Business Continuity Program

The PNC Financial Services Group, Inc. Business Continuity Program The PNC Financial Services Group, Inc. Business Continuity Program 1 Content Overview A. Introduction Page 3 B. Governance Model Page 4 C. Program Components Page 4 Business Impact Analysis (BIA) Page

More information

BUSINESS CONTINUITY MANAGEMENT SINGAPORE SS540 BCM STANDARDS. LSA Consultants Pte Ltd

BUSINESS CONTINUITY MANAGEMENT SINGAPORE SS540 BCM STANDARDS. LSA Consultants Pte Ltd BUSINESS CONTINUITY MANAGEMENT SINGAPORE SS540 BCM STANDARDS LSA Consultants Pte Ltd BCM SINGAPORE LSA Consultants Who are we? Business Continuity Management (BCM) What is it? Singapore Standard SS540

More information

Institute for Business Continuity Training 1623 Military Road, # 377 Niagara Falls, NY 14304-1745

Institute for Business Continuity Training 1623 Military Road, # 377 Niagara Falls, NY 14304-1745 ECP - 601: Effective Business Continuity Management: ISO 22301 This 3-day course provides an intensive, hands-on workshop covering all major aspects for the design of an effective Business Continuity Plan

More information

Plan Development Getting from Principles to Paper

Plan Development Getting from Principles to Paper Plan Development Getting from Principles to Paper March 22, 2015 Table of Contents / Agenda Goals of the workshop Overview of relevant standards Industry standards Government regulations Company standards

More information

BCP and DR. P K Patel AGM, MoF

BCP and DR. P K Patel AGM, MoF BCP and DR P K Patel AGM, MoF Key difference between BS 25999 and ISO 22301 ISO 22301 puts a much greater emphasis on setting the objectives, monitoring performance and metrics aligning BC to top management

More information

CHAPTER 1: BUSINESS CONTINUITY MANAGEMENT STRATEGY AND POLICY

CHAPTER 1: BUSINESS CONTINUITY MANAGEMENT STRATEGY AND POLICY Zurich Management Services Limited Registered in England: No 2741053 Registered Office The Zurich Centre, 3000 Parkway Whiteley, Fareham Hampshire, PO15 7JZ CHAPTER 1: BUSINESS CONTINUITY MANAGEMENT STRATEGY

More information

AUDITING A BCP PLAN. Thomas Bronack Auditing a BCP Plan presentation Page: 1

AUDITING A BCP PLAN. Thomas Bronack Auditing a BCP Plan presentation Page: 1 AUDITING A BCP PLAN Thomas Bronack Auditing a BCP Plan presentation Page: 1 What are the Objectives of a Good BCP Plan Protect employees Restore critical business processes or functions to minimize the

More information

Coping with a major business disruption. Some practical advice

Coping with a major business disruption. Some practical advice Coping with a major business disruption Some practical advice Coping with a major business disruption What is business continuity? Business continuity planning (BCP) is a management process that helps

More information

BS 25999 BUSINESS CONTINUITY MANAGEMENT

BS 25999 BUSINESS CONTINUITY MANAGEMENT BS 25999 BUSINESS CONTINUITY MANAGEMENT AUDIT, CERTIFICATION & training services HOW CAN YOU ENSURE BUSINESS CONTINUITY? BS 25999 AUDITS & CERTIFICATION FROM SGS Most organisations will, at some point,

More information

Global Statement of Business Continuity

Global Statement of Business Continuity Business Continuity Management Version 1.0-2014 Date October 18, 2014 Status Author Business Continuity Management (BCM) Page 1 of 8 Table of Contents 1. Credit Suisse Business Continuity Statement 3 2.

More information

Business Continuity Management Review

Business Continuity Management Review Office of Internal Audit Business Continuity Management Review November 14, 2014 Internal Audit Team Shannon Henry Chief Audit Officer & Executive Director of Institutional Compliance Stacy Sneed Audit

More information

Business Continuity Planning and Disaster Recovery Planning

Business Continuity Planning and Disaster Recovery Planning 4 Business Continuity Planning and Disaster Recovery Planning Basic Concepts 1. Business Continuity Management: Business Continuity means maintaining the uninterrupted availability of all key business

More information

PAPER-6 PART-1 OF 5 CA A.RAFEQ, FCA

PAPER-6 PART-1 OF 5 CA A.RAFEQ, FCA 1 Chapter-4: Business Continuity Planning and Disaster Recovery Planning PAPER-6 PART-1 OF 5 CA A.RAFEQ, FCA Learning Objectives 2 To understand the concept of Business Continuity Management To understand

More information

NHS Hardwick Clinical Commissioning Group. Business Continuity Policy

NHS Hardwick Clinical Commissioning Group. Business Continuity Policy NHS Hardwick Clinical Commissioning Group Business Continuity Policy Version Date: 26 January 2016 Version Number: 2.0 Status: Approved Next Revision Due: January 2017 Gordon Stevens MBCI Corporate Assurance

More information

Sustainability through Business Continuity Management

Sustainability through Business Continuity Management Sustainability through Business Continuity Management R Vaidhyanathan (RV) MBCI,CBCP, TE BS25999, BS25999LA, BCCE, 27001LA, ITIL Practice Head for Crisis Management & BCM Continuity and Resilience (CORE)

More information

Business Continuity Management

Business Continuity Management Business Continuity Management Policy Statement & Strategy July 2009 Basildon District Council Business Continuity Management Policy Statement The Council is committed to ensuring robust and effective

More information

Birmingham CrossCity Clinical Commissioning Group. Business Continuity Management Policy

Birmingham CrossCity Clinical Commissioning Group. Business Continuity Management Policy Birmingham CrossCity Clinical Commissioning Group Business Continuity Management Policy Version V1.0 Ratified by Operational Development Group Date ratified 6 th November 2014 Name of originator / author

More information

Business Resilience and Risk Management

Business Resilience and Risk Management Policy Business Resilience and Risk Management Document Number GOV-POL-37 1.0 Policy Statement Stanwell is committed to delivering a business resilience platform across all levels of the business and its

More information

Business Continuity Management Framework

Business Continuity Management Framework Business Continuity Management Framework Date of Issue: November 2013 Review Date: November 2014 Written by: Jackie Orchard Risk & Business Continuity Manager Authorised by: Signed off by: DCC Francis

More information

Kuala Lumpur, Malaysia, 25 26 May 2010. Report

Kuala Lumpur, Malaysia, 25 26 May 2010. Report Cooperative Arrangement for the Prevention of Spread of Communicable Disease through Air travel (CAPSCA) Workshop / Seminar on Aviation Business Continuity Planning Kuala Lumpur, Malaysia, 25 26 May 2010

More information

Emergency Response and Business Continuity Management Policy

Emergency Response and Business Continuity Management Policy Emergency Response and Business Continuity Management Policy Owner: John Duffy, Registrar & Secretary Last updated: September 2012 Version: 04 Document control Date Version Author Changes To be populated

More information

BUSINESS CONTINUITY MANAGEMENT FRAMEWORK

BUSINESS CONTINUITY MANAGEMENT FRAMEWORK BUSINESS CONTINUITY MANAGEMENT FRAMEWORK Document Author: Civil Contingencies Service - Authorised by the CCS Joint Management Board - Version 1.0. Issued December 2012 Page 1 FRAMEWORK STATEMENT Business

More information

Business Continuity Management

Business Continuity Management Business Continuity Management Factsheet To prepare for change, change the way you prepare In an intensely competitive environment, a permanent market presence is essential in order to satisfy customers

More information

ISO 22301:2012 Societal Security Appendix B Business Continuity Management Systems Requirements 347

ISO 22301:2012 Societal Security Appendix B Business Continuity Management Systems Requirements 347 Appendix B Business Continuity Management Systems Requirements 347 B.3 Format and Structure ISO 22301 is the second published standard to adopt ISO s new high-level structure for management systems standards

More information

Moving from BS 25999-2 to ISO 22301. The new international standard for business continuity management systems. Transition Guide

Moving from BS 25999-2 to ISO 22301. The new international standard for business continuity management systems. Transition Guide Transition Guide Moving from BS 25999-2 to ISO 22301 The new international standard for business continuity management systems Extract from The Route Map to Business Continuity Management: Meeting the

More information

Overview TECHIS60851. Manage information security business resilience activities

Overview TECHIS60851. Manage information security business resilience activities Overview Information security business resilience encompasses business continuity and disaster recovery from information security threats. As well as addressing the consequences of a major security incident,

More information

Business Continuity Management

Business Continuity Management Business Continuity Management Standard Operating Procedure Notice: This document has been made available through the Police Service of Scotland Freedom of Information Publication Scheme. It should not

More information

BCM and DRP - RFP Template

BCM and DRP - RFP Template BCM and DRP - The Supreme Council of Information & Communication Technology ictqatar PUBLICATION DATE Document Reference This document should be used as an example of the contents of an RFP for business

More information

KPMG Information Risk Management Business Continuity Management Peter McNally, KPMG Asia Pacific Leader for Business Continuity

KPMG Information Risk Management Business Continuity Management Peter McNally, KPMG Asia Pacific Leader for Business Continuity INFORMATION RISK MANAGEMENT KPMG Information Risk Management Business Continuity Management Peter McNally, KPMG Asia Pacific Leader for Business Continuity ADVISORY Contents Agenda: Global trends and BCM

More information

BSO Board Director of Human Resources & Corporate Services Business Continuity Policy. 28 February 2012

BSO Board Director of Human Resources & Corporate Services Business Continuity Policy. 28 February 2012 To: From: Subject: Status: Date of Meeting: BSO Board Director of Human Resources & Corporate Services Business Continuity Policy For Approval 28 February 2012 The Board is asked to agree the attached

More information

Principles for BCM requirements for the Dutch financial sector and its providers.

Principles for BCM requirements for the Dutch financial sector and its providers. Principles for BCM requirements for the Dutch financial sector and its providers. Platform Business Continuity Vitale Infrastructuur Financiële sector (BC VIF) Werkgroep BCM requirements 21 September 2011

More information

WEST YORKSHIRE FIRE & RESCUE SERVICE. Business Continuity Management Strategy

WEST YORKSHIRE FIRE & RESCUE SERVICE. Business Continuity Management Strategy WEST YORKSHIRE FIRE & RESCUE SERVICE Business Continuity Management Strategy Date Issued: 12 November 2012 Review Date: 12 November 2015 Version Control Version Number Date Author Comment 0.1 June 2011

More information

Business Continuity and Risk Management. Ken Kaberia Principal BCM Officer, Enterprise Risk Safaricom Limited

Business Continuity and Risk Management. Ken Kaberia Principal BCM Officer, Enterprise Risk Safaricom Limited Business Continuity and Risk Management Ken Kaberia Principal BCM Officer, Enterprise Risk Safaricom Limited What does Business Continuity mean? Business Continuity Management- Definition Business Continuity

More information

Business Continuity and Disaster Recovery Planning

Business Continuity and Disaster Recovery Planning Business Continuity and Disaster Recovery Planning Jennifer Brandt, CISA A p r i l 16, 2015 HISTORY OF STINNETT & ASSOCIATES Stinnett & Associates (Stinnett) is a professional advisory firm offering services

More information

JOB ANNOUNCEMENT. Chief Security Officer, Cheniere Energy, Inc.

JOB ANNOUNCEMENT. Chief Security Officer, Cheniere Energy, Inc. JOB ANNOUNCEMENT Chief Security Officer, Cheniere Energy, Inc. Position Overview The Vice President and Chief Security Risk Officer (CSRO) reports to the Chairman, Chief Executive Officer and President

More information

Business Continuity Management Software

Business Continuity Management Software Business Continuity Management (BCM) Software 1 Business Continuity Management Software All In One Continuity Management Solution A Single Platform Approach Manage entire lifecycle with comprehensive BC

More information

Business Continuity Planning for Water Utilities: Guidance Document [Project #4319]

Business Continuity Planning for Water Utilities: Guidance Document [Project #4319] Business Continuity Planning for Water Utilities: Guidance Document [Project #4319] ORDER NUMBER: 4319 DATE AVAILABLE: June 2013 PRINCIPAL INVESTIGATORS: Jack Moyer, Rhiannon Kincaid, Kory Wilmot, Kate

More information

RSA ARCHER BUSINESS CONTINUITY MANAGEMENT AND OPERATIONS Solution Brief

RSA ARCHER BUSINESS CONTINUITY MANAGEMENT AND OPERATIONS Solution Brief RSA ARCHER BUSINESS CONTINUITY MANAGEMENT AND OPERATIONS Solution Brief INTRODUCTION Now more than ever, organizations depend on services, business processes and technologies to generate revenue and meet

More information

ESCB definitions of major business continuity terms in relation to payment and securities settlement systems 1

ESCB definitions of major business continuity terms in relation to payment and securities settlement systems 1 ESCB definitions of major business continuity terms in relation to payment and securities settlement systems 1 June 2007 The ESCB has developed a glossary of major business continuity terms for market

More information

The Resilient IT Infrastructure

The Resilient IT Infrastructure The Resilient IT Infrastructure Jeremy Wong Senior Vice President BCM Institute Republic Polytechnic, Block W4, Level 1, LR-W4B 25 November 2013 Jeremy Wong Senior Vice President Business Continuity Management

More information

Subject Area 1 Project Initiation and Management

Subject Area 1 Project Initiation and Management DRII/BCI Professional Practice Narrative: Establish the need for a Business Continuity Plan (BCP), including obtaining management support and organizing and managing the BCP project to completion. (This

More information

CONTINUITY OF OPERATIONS AUDIT PROGRAM EVALUATION AND AUDIT

CONTINUITY OF OPERATIONS AUDIT PROGRAM EVALUATION AND AUDIT CONTINUITY OF OPERATIONS AUDIT PROGRAM EVALUATION AND AUDIT April 16, 2014 INTRODUCTION Purpose The purpose of the audit is to give assurance that the development of the Metropolitan Council s Continuity

More information

Business Continuity Policy and Business Continuity Management System

Business Continuity Policy and Business Continuity Management System Business Continuity Policy and Business Continuity Management System Summary: This policy sets out the structure for ensuring that the PCT has effective Business Continuity Plans in place in order to maintain

More information

Business Continuity Standards A Primer

Business Continuity Standards A Primer INTELLIGENT NOTIFICATION Alphabet Soup: Making Sense of BC/DR Standards Part 1: Business Continuity Standards A Primer Why all the attention now? One of the hottest topics in BC/DR these days is standards.

More information

Business Continuity Management. Policy Statement and Strategy

Business Continuity Management. Policy Statement and Strategy Business Continuity Management Policy Statement and Strategy November 2011 Title Business Continuity Management Policy & Strategy Date of Publication: Cabinet Council Published by Borough Council of King

More information

COMCARE BUSINESS CONTINUITY MANAGEMENT

COMCARE BUSINESS CONTINUITY MANAGEMENT COMCARE BUSINESS CONTINUITY MANAGEMENT Title Business Continuity Management Version 2.1 Authorised by Executive Committee Effective date Authorisation date 10/7/2012 10/7/2012 COMCARE BUSINESS CONTINUITY

More information

Solihull Clinical Commissioning Group

Solihull Clinical Commissioning Group Solihull Clinical Commissioning Group Business Continuity Policy Version v1 Ratified by SMT Date ratified 24 February 2014 Name of originator / author CSU Corporate Services Review date Annual Target audience

More information

With the large number of. How to Avoid Disaster: RIM s Crucial Role in Business Continuity Planning. Virginia A. Jones, CRM, FAI RIM FUNDAMENTALS

With the large number of. How to Avoid Disaster: RIM s Crucial Role in Business Continuity Planning. Virginia A. Jones, CRM, FAI RIM FUNDAMENTALS How to Avoid Disaster: RIM s Crucial Role in Business Continuity Planning The world has experienced a great deal of natural and man-made upheaval and destruction in the past few years, including tornadoes,

More information

NORTH HAMPSHIRE CLINICAL COMMISSIONING GROUP BUSINESS CONTINUITY MANAGEMENT POLICY AND PLAN (COR/017/V1.00)

NORTH HAMPSHIRE CLINICAL COMMISSIONING GROUP BUSINESS CONTINUITY MANAGEMENT POLICY AND PLAN (COR/017/V1.00) NORTH HAMPSHIRE CLINICAL COMMISSIONING GROUP BUSINESS CONTINUITY MANAGEMENT POLICY AND PLAN (COR/017/V1.00) Subject and version number of document: Serial Number: Business Continuity Management Policy

More information

The Weill Cornell Medical College and Graduate School of Medical Sciences. Responsible Department: Information Technologies and Services (ITS)

The Weill Cornell Medical College and Graduate School of Medical Sciences. Responsible Department: Information Technologies and Services (ITS) Information Technology Disaster Recovery Policy Policy Statement This policy defines acceptable methods for disaster recovery planning, preparedness, management and mitigation of IT systems and services

More information

Chapter I: Fundamentals of Business Continuity Management

Chapter I: Fundamentals of Business Continuity Management Chapter I: Fundamentals of Business Continuity Management Objectives Define Business Continuity Management (BCM) Define the relationship between BCM and risk management Review BCM responsibilities Identify

More information

Business Continuity Management

Business Continuity Management GENERALLY ACCESSIBLE Business Continuity Management Field Report from an Audit Point of View ISACA Swiss Chapter - After Hour Seminar 28 August 2006 - Urs Voigt - Group Internal Audit Disasters Happen

More information

Business Continuity Plan

Business Continuity Plan Business Continuity Plan October 2007 Agenda Business continuity plan definition Evolution of the business continuity plan Business continuity plan life cycle FFIEC & Business continuity plan Questions

More information

Effective risk management

Effective risk management Effective risk management Our holistic and disciplined risk management program is designed to mitigate risks at all levels of our business in order to protect our clients interests. 2 Vanguard > Effective

More information

CSC AND THE BUSINESS CONTINUITY MATURITY ASSESSMENT PROGRAM

CSC AND THE BUSINESS CONTINUITY MATURITY ASSESSMENT PROGRAM A WHITE PAPER CSC AND THE BUSINESS CONTINUITY MATURITY ASSESSMENT PROGRAM AUTHORS: Neil A. Smith, MBCP [email protected] Sandra Riddell, MBCI [email protected] CSC Papers 2013 ABSTRACT The auditors said

More information

Business Continuity Management Governance. Frank Higgins Abu Dhabi March 2015

Business Continuity Management Governance. Frank Higgins Abu Dhabi March 2015 Business Continuity Management Governance Frank Higgins Abu Dhabi March 2015 Different Names Same Concept BCM (Business Continuity Management) BSI 25999 IPOCM (Incident Preparedness & Operational Continuity

More information

CENTRAL BANK OF KENYA (CBK) PRUDENTIAL GUIDELINE ON BUSINESS CONTINUITY MANAGEMENT (BCM) FOR INSTITUTIONS LICENSED UNDER THE BANKING ACT

CENTRAL BANK OF KENYA (CBK) PRUDENTIAL GUIDELINE ON BUSINESS CONTINUITY MANAGEMENT (BCM) FOR INSTITUTIONS LICENSED UNDER THE BANKING ACT CENTRAL BANK OF KENYA (CBK) PRUDENTIAL GUIDELINE ON BUSINESS CONTINUITY MANAGEMENT (BCM) FOR INSTITUTIONS LICENSED UNDER THE BANKING ACT JANUARY 2008 GUIDELINE ON BUSINESS CONTINUITY GUIDELINE CBK/PG/14

More information

Leveraging the IT Service Continuity Management framework Gord Novoselnik Business Continuity Office Enterprise Solutions Division

Leveraging the IT Service Continuity Management framework Gord Novoselnik Business Continuity Office Enterprise Solutions Division Leveraging the IT Service Continuity Management framework Gord Novoselnik Business Continuity Office Enterprise Solutions Division 1 MTS Allstream Inc. proprietary. Use pursuant to company instructions./

More information

Business Continuity Management Program Development Guide

Business Continuity Management Program Development Guide Business Continuity Management Program Development Guide Prepared by The NS Emergency Management Office, Winter 2012 Version 1.1 Page 2 of 24 Document Revision History Date Author Revision Notes Fall 2011

More information

BUSINESS CONTINUITY POLICY

BUSINESS CONTINUITY POLICY BUSINESS CONTINUITY POLICY Document Type Corporate Policy Unique Identifier CO-038 Document Purpose To provide a structure through which: i. A comprehensive business continuity management system (BCMS)

More information

Business Continuity Management Policy

Business Continuity Management Policy Business Continuity Management Policy Policy Holder: Authoriser: Caroline Gover, Head of Business Continuity Caroline Thomson, Chief Operating Officer Reviewed on: Feb 08 Reviewed on: Feb 08 Next Review

More information

Business Continuity Policy

Business Continuity Policy Business Continuity Policy Summary: This policy sets out the structure for ensuring that the PCT has effective Business Continuity Plans in place in order to maintain its essential business functions during

More information

A BCP Tale: From Theory to Practice

A BCP Tale: From Theory to Practice A BCP Tale: From Theory to Practice Presenter: Gord Novoselnik Problem & Configuration Manager, Enterprise Solutions Division, MTS Allstream [email protected] 1 10 Commandments of BCM I.

More information

BC / DR Implementation Tying Disaster Recovery Investment to Measurable Business Value

BC / DR Implementation Tying Disaster Recovery Investment to Measurable Business Value BC / DR Implementation Tying Disaster Investment to Measurable Business Value Continuity Insights Conference May 16-18, 2005 Agenda Purpose Discuss best practice process and tools that might be leveraged

More information

Planning for Disaster. Ramesh Ramani CISM CGEIT [email protected] 02 June 2010

Planning for Disaster. Ramesh Ramani CISM CGEIT ramani@pcsuae.com 02 June 2010 Planning for Disaster Ramesh Ramani CISM CGEIT [email protected] 02 June 2010 Agenda Disaster Management-Introduction Examples BCP and IT Continuity Process of Disaster Management-PDCA Disaster Management

More information

ISO 22301: Societal Security Terminology ISO 22313: BCMS Guidance ISO 22398: Exercises and Testing - Guidance

ISO 22301: Societal Security Terminology ISO 22313: BCMS Guidance ISO 22398: Exercises and Testing - Guidance The Impact of ISO 22301 Moving Your BCM Program to a Management System Implementing the Newly Approved International Business Continuity Management System Standard & Guidance Documents ISO 22301: Societal

More information

HB 292 2006 A Practitioners Guide to Business Continuity Management

HB 292 2006 A Practitioners Guide to Business Continuity Management HB 292 2006 A Practitioners Guide to Business Continuity Management HB HB 292 2006 Handbook A practitioners guide to business continuity management First published as HB 292 2006. COPYRIGHT Standards Australia

More information

Il nuovo standard ISO 22301 sulla Business Continuity Scenari ed opportunità

Il nuovo standard ISO 22301 sulla Business Continuity Scenari ed opportunità Il nuovo standard ISO 22301 sulla Business Continuity Scenari ed opportunità Massimo Cacciotti Business Services Manager BSI Group Italia Agenda BSI: Introduction 1. Why we need BCM? 2. Benefits of BCM

More information

CISM ITEM DEVELOPMENT GUIDE

CISM ITEM DEVELOPMENT GUIDE CISM ITEM DEVELOPMENT GUIDE Updated January 2015 TABLE OF CONTENTS Content Page Purpose of the CISM Item Development Guide 3 CISM Exam Structure 3 Writing Quality Items 3 Multiple-Choice Items 4 Steps

More information

NEEDS BASED PLANNING FOR IT DISASTER RECOVERY

NEEDS BASED PLANNING FOR IT DISASTER RECOVERY The Define/Align/Approve Reference Series NEEDS BASED PLANNING FOR IT DISASTER RECOVERY Disaster recovery planning is essential it s also expensive. That s why every step taken and dollar spent must be

More information

Business Continuity Planning. A guide to loss prevention

Business Continuity Planning. A guide to loss prevention Business Continuity Planning A guide to loss prevention There are many statistics quoted about the effect that a lack of planning for a disaster has on a business. What s certain is that any unplanned

More information

Business Continuity Policy

Business Continuity Policy Business Continuity Policy St Mary Magdalene Academy V1.0 / September 2014 Document Control Document Details Document Title Document Type Business Continuity Policy Policy Version 2.0 Effective From 1st

More information

Introduction UNDERSTANDING BUSINESS CONTINUITY MANAGEMENT

Introduction UNDERSTANDING BUSINESS CONTINUITY MANAGEMENT INFORMATION SECURITY: UNDERSTANDING BUSINESS CONTINUITY MANAGEMENT FACTSHEET This factsheet will introduce you to Business Continuity Management (BCM), which is a process developed to counteract systems

More information

Update from the Business Continuity Working Group

Update from the Business Continuity Working Group 23 June 2014 Performance and Resources Board 19 To note Update from the Business Continuity Working Group Issue 1 The Business Continuity Working Group oversees the development, maintenance and improvement

More information

PBSi Business Continuity Planning

PBSi Business Continuity Planning Business Continuity Planning Definition Business Continuity planning is a planning process designed to reduce the risk that disruptive failures or events could seriously harm your business. It is designed

More information

NHS ISLE OF WIGHT CLINICAL COMMISSIONING GROUP BUSINESS CONTINUITY POLICY

NHS ISLE OF WIGHT CLINICAL COMMISSIONING GROUP BUSINESS CONTINUITY POLICY NHS ISLE OF WIGHT CLINICAL COMMISSIONING GROUP BUSINESS CONTINUITY POLICY AUTHOR/ APPROVAL DETAILS Document Author Written By: Human Resources Authorised Signature Authorised By: Helen Shields Date: 20

More information